You can try adding the following firewall rules.

iptables -I FORWARD -m conntrack --ctstate DNAT -j ACCEPT